Skip to main content

CVE detail

CVE-2014-0502

Double free vulnerability in Adobe Flash Player before 11.7.700.269 and 11.8.x through 12.0.x before 12.0.0.70 on Windows and Mac OS X and before 11.2.202.341 on Linux, Adobe AIR before 4.0.0.1628 on Android, Adobe AIR SDK before 4.0.0.1628, and Adobe AIR SDK & Compiler before 4.0.0.1628 allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2014.

CVSS 8.8 · HighBuzz score 59.0KEV listed

Buzz score

Why this CVE is surfacing

Buzz score total 59.0

This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.

Buzz score components · mention 23.0 · diversity 11.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Mention score
23.0
9 evidence mentions in the snapshot
Diversity score
11.0
5 sources across 1 categories
KEV score
25.0
Known exploited vulnerability present
OTX score
0.0
0 OTX pulses
PoC score
0.0
0 repos · best confidence N/A
Best PoC traction
0
Maximum stars on a matched PoC repo

Why it matters now

Mention timeline

Total mentions
0
within the 30d window
Peak daily
0
highest bucket

Evidence

Source links by recency

Newest mentions first
9 source links · newest first
  • After analyzing public vulnerabilities and exploit trends in the first half of 2014, Bromium Labs concluded that Internet Explorer is the “sweet spot for attackers.” “Internet Explorer was the most patched and also one of the most exploited products,” the report (pdf) states. Microsoft’s browser “set a record high for reported vulnerabilities in the first […]

    newswww.csoonline.comJul 23, 2014, 3:23 PM
  • Attackers are targeting vulnerabilities in major Web browsers to compromise cloud-based point-of-sale (PoS) systems, according to cyber threat intelligence firm, IntelCrawler. The malware, called POSCLOUD by IntelCrawler, targets cloud-based PoS software commonly used by grocery stores, retailers, and other small businesses, the company wrote in a report released Wednesday. Unlike most PoS malware, POSCLOUD doesn’t bother with RAM scraping to intercept payment card information before the system gets a chance to encrypt the data. Instead, the malware relies on keylogging and stealth screenshots to steal personal information and financial data, which are then sold on underground forums to identity thieves, IntelCrawler said. Researchers initially uncovered the malware after a big botnet takedown, said Andrew Komarov, CEO of IntelCrawler. Many of these cloud systems integrate with locally-attached hardware such as credit card readers, barcode scanners, cash drawers, and receipt printer a…

    newswww.securityweek.comJun 12, 2014, 8:05 PM
  • Experts at Symantec have discovered that behind the Elderwood Platform there is a still active group which is providing Zero-Day exploit used recently. Do you remember the Elderwood project? It was September 2012 when Symantec security firm published an analysis that demonstrate the link between a series of cyber attacks against more than 30 companies and the cyber […]

    newssecurityaffairs.comMay 17, 2014, 4:19 AM
  • Further investigation into an exploit kit known as “Elderwood” shows the attackers using it are more numerous and possibly better funded than previously thought, according to new research from Symantec. Elderwood is a hacking platform that has attack code which abuses software vulnerabilities in programs such as Adobe Systems’ Flash multimedia program and Microsoft’s Internet […]

    newswww.csoonline.comMay 16, 2014, 1:30 PM
  • Researchers at Symantec say the Elderwood attack platform is at the center of numerous zero-day attacks launched by hacker crews around the world this year.

    newswww.securityweek.comMay 15, 2014, 5:46 PM
  • Here’s an overview of some of last week’s most interesting news, reviews, articles and interviews: (IN)SECURE Magazine issue 41 released (IN)SECURE Magazine is a free digital security publication discussing some of the hottest information security topics. Issue 41 has been released today. Exploring the complexity of modern cyber attacks James Holley is an Executive Director at Ernst & Young LLP. In this interview he discusses the complexity of modern cyber attacks, the challenges involved in … More →

    newswww.helpnetsecurity.comFeb 24, 2014, 12:00 AM
  • Adobe fixes Flash 0-dayHelp Net Security

    Adobe released their second out-of-band update for Adobe Flash this month. APSB14-07 fixes three vulnerabilities in Adobe Flash, including CVE-2014-0502 which is being used in the wild to attack users through malicious webpages. The 0-day flaw in Flash CVE-2014-0502 was discovered about a week ago by FireEye which states that it was found on three websites that are run by non-profit institutions. Fortunately organizations that are running latest operating systems and application code are not … More →

    newswww.helpnetsecurity.comFeb 21, 2014, 2:01 AM
  • Adobe Systems issued critical security updates today to address vulnerabilities in Adobe Flash Player – including one vulnerability that is under attack.

    newswww.securityweek.comFeb 20, 2014, 6:36 PM
  • Adobe Flash Player Zero-Day: details and mitigationMalwarebytes Labs

    Update (02/24/14): This exploit has been found in the wild already. It is blocked by Malwarebytes Anti-Exploit.In a very busy month for…

    newswww.malwarebytes.comFeb 19, 2014, 5:00 PM

Exploit code

Public exploit repository references

Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.

0 repository references · best confidence N/A · max 0 stars
No public PoC repositories have been matched yet.

Related records

Similar CVEs

6 related CVEs with shared weakness or product evidence